Cybersecurity

CVE Vulnerability Alerts
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
Cisco patched a critical authentication bypass in Catalyst SD-WAN Manager, formerly vManage, that attackers are actively exploiting to seize full admin control.
Cybersecurity
MetaMask Discloses Incident, Exits Ethereum Validators
MetaMask disclosed a security incident affecting its staking infrastructure and is proactively exiting Ethereum validators it runs through the Lido protocol.
CVE Vulnerability Alerts
TeamViewer Patches Critical Access-Control Bypass Flaw
TeamViewer patched a critical access-control bypass and four other flaws in its Full Client and Host software, urging all users to update immediately.
CVE Vulnerability Alerts
WatchGuard Patches Critical Root Code Execution Flaw
WatchGuard patched a critical Fireware OS flaw letting a rogue VPN server run root commands on Firebox appliances, plus 14 other bugs in the same ...
CVE Vulnerability Alerts
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
CISA warned that a pre-authentication flaw in MikroTik RouterOS lets a single crafted request trigger root code execution or crash the device remotely.
Cybersecurity
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
The FTC confirmed it is investigating OpenAI, Anthropic, and other AI firms after agents reportedly went beyond instructions to hack external websites.
Cybersecurity
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
A 16-year-old researcher used a self-built AI tool to gain admin access to Microsoft's internal Titan analytics platform, exposing 17.3 trillion rows.
CVE Vulnerability Alerts
OpenSSL Patches High-Severity DTLS Memory Leak Flaw
OpenSSL patched a high-severity DTLS flaw that can expose unencrypted heap memory or crash affected software running its widely used cryptographic library.
Cybersecurity
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
A phishing campaign dubbed CSuite is hijacking executives' Microsoft 365 sessions and installing ScreenConnect and Action1 for persistent remote access.
Application Security
Chrome, Firefox Patch Over 100 Flaws in Joint Update
Chrome and Firefox fixed over 100 vulnerabilities between them, including a critical ANGLE buffer overflow in Chrome rated capable of remote code execution.